Techub News reported that Ethereum sandwich attack bot jaredfromsubway.eth was exploited for more than $7.5 million. Security firm Blockaid said the attackers used a forged token contract to trick the bot into approving a malicious helper contract, then used the open authorization to transfer funds. The incident was reported by CoinDesk.
jaredfromsubway.eth has long been responsible for about 70% of sandwich attacks on Ethereum. A sandwich attack generally refers to an on-chain trading strategy that places transactions around a target transaction, relying on automated systems to identify and execute trades quickly. In this case, the attack did not target a vulnerability in the bot’s own contract. Instead, it targeted the bot’s automated decision-making process.
According to Blockaid, the attackers deployed fake liquidity pools and simulated profitable-looking trading opportunities to induce the bot to approve and interact with the setup. Once the malicious helper contract received authorization, funds were moved out. The input information states that part of the stolen funds has already been transferred through Tornado Cash.

